CVE Vulnerabilities

CVE-2009-2518

Published: Oct 14, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka Office BMP Integer Overflow Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
OfficeMicrosoftxp-sp3 (including)xp-sp3 (including)

References